Overview 14 indicators
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.
| ipv4 | 11 | G1034.json |
| domain | 3 | G1034-domain.txt |
Techniques 17 ATT&CK
Open in ATT&CK Navigator → or download the layer (17 techniques, layer 4.5)
- T1003.002 Security Account Manager
- T1012 Query Registry
- T1036.003 Rename Legitimate Utilities
- T1053.005 Scheduled Task
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1136.001 Local Account
- T1189 Drive-by Compromise
- T1195.002 Compromise Software Supply Chain
- T1204.001 Malicious Link
- T1218.011 Rundll32
- T1553.002 Code Signing
- T1574.001 DLL
- T1584.004 Server
- T1587.002 Code Signing Certificates
Software 6
Principal sources 17 reports
Ranked by how many of this actor's indicators each report brought in.
- 5twitter.com/h2jazi/status/1296919948598673409
- 5blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro…
- 5otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f
- 5virustotal.com/gui/domain/governmentmm.com/relations
- 5app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…
- 4x.com/TuringAlex/status/1859969605084823621
- 4bleepingcomputer.com/news/security/chinese-cyberspies-use-ne…
- 4virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…
Timeline 14 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/TuringAlex/status/1859969605084823621 · bleepingcomputer.com/news/security/chinese-cyberspies-use-ne… · virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…
45.125.64.200:33200 -
x.com/TuringAlex/status/1859969605084823621 · bleepingcomputer.com/news/security/chinese-cyberspies-use-ne… · virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…
223.165.4.175:81 45.125.64.200:33220 45.125.64.200:33223 -
symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage… · virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f… · virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6e… · virustotal.com/gui/file/23acab55f533cad2471516d15f52a8… · virustotal.com/gui/file/dfd28fa39cfa6a8e06ea897a6df78f… · virustotal.com/gui/file/a0b125e69a8b3619b372fe363bd2cf… · virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4d… · virustotal.com/gui/file/82a662cc06c49714efd8ed9086e201…
103.96.128.44:10001 103.96.128.44:16564 103.96.131.150:19876 103.96.131.150:40020 -
welivesecurity.com/en/eset-research/evasive-panda-leverage…
update.devicebug.com -
twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…
45.77.140.81:81 -
twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…
domain governmentmm.com ipv4 122.10.89.170:9552 ipv4 122.10.89.172:10560 -
twitter.com/h2jazi/status/1296919948598673409 · blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro… · otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f · virustotal.com/gui/domain/governmentmm.com/relations · app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…
flash.governmentmm.com
Further reading 20
- attack.mitre.org/groups/G1034
- symantec-enterprise-blogs.security.com/threat-intelligence/apt-attacks-telecom…
- symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage…
- welivesecurity.com/2023/04/26/evasive-panda-apt-group-malw…
- welivesecurity.com/en/eset-research/evasive-panda-leverage…
- app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04…
- virustotal.com/gui/file/a0b125e69a8b3619b372fe363bd2cf…
- bleepingcomputer.com/news/security/chinese-cyberspies-use-ne…
- virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6e…
- x.com/TuringAlex/status/1859969605084823621
- otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f
- virustotal.com/gui/domain/governmentmm.com/relations
- virustotal.com/gui/file/82a662cc06c49714efd8ed9086e201…
- virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4d…
- twitter.com/h2jazi/status/1296919948598673409
- virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f…
- virustotal.com/gui/file/dfd28fa39cfa6a8e06ea897a6df78f…
- virustotal.com/gui/file/23acab55f533cad2471516d15f52a8…
- blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-gro…
- virustotal.com/gui/file/94e8540ea39893b6be910cfee03317…